Last updated 27 July 2026

Privacy policy

This page explains what Airrow stores when you use airrow.app, why it is stored, and who else can see it. It describes the product as it is built, not as a generic template.

What we store

  • Account data. Your email address, your display name, and the authentication record held by our auth provider. Passwords are never stored in readable form.
  • Project data. Your interview answers, the project model derived from them, and the documents generated for you. This is your intellectual property and we treat it that way.
  • Imported project structure. If you import an existing project, we store its shape — the file names, their sizes, and a keyed fingerprint of each file — so we can show you the structure and work out what we would add. We do not store the contents of your files. They are read in memory while we analyse the archive and are never written down or logged. That is also why a download of an imported project is assembled in your browser: your code stays on your machine.
  • Operational logs. Request metadata, identifiers, timestamps and errors. Logs deliberately carry IDs and metadata only, never your answers or the contents of generated documents.

Why we store it

To run the service you asked for: authenticate you, keep your projects separate from everyone else's, generate your foundation, and let you download it again later. We also keep the minimum needed to secure accounts and diagnose failures. We do not sell your data, and we do not use it for advertising.

Who processes it

  • Vercel hosts the application and serves it over its network, and provides the cookieless analytics that counts visits to our public pages. It stores nothing on your device and produces aggregate counts only — never a profile, and never anything joined to your account. The cookie policy describes exactly what it records.
  • PostHog receives product events — that an interview was started, that a foundation was generated, that a subscription began — so we can see where people get stuck. It receives no email address, no name, none of your interview answers and none of your generated documents; what identifies an event is an opaque workspace identifier that means nothing outside our database. Like the visit count above, it stores nothing on your device.
  • Supabase provides the database, authentication and file storage where your projects live.
  • Anthropic receives the parts of your project model needed to author your documents, and processes them under its API terms to return the generated text.

These are processors acting on our instructions. We add no advertising, profiling or session-recording services, and our analytics is cookieless throughout — the visit count and the product events described above, nothing that follows you between sites, and nothing that identifies you.

Our own staff. A small number of Airrow personnel can access project data — including your interview answers — through an internal administration tool, and only where it is needed to deliver and support the service: answering a support request, investigating a generation that failed, or acting on a problem with an account. Access is restricted to named administrator accounts, actions taken on an account are recorded with who took them and why, and nothing seen this way is written to our logs. We do not read your project data for any other purpose, and we still never store the contents of files you import.

How it is protected

Every resource belongs to an organization, and access is enforced in the database itself through row-level security as well as in the application. Data is encrypted at rest, downloads are served through short-lived signed links, and repository access, where you connect it, uses scoped app installations rather than personal access tokens.

How long it is kept

Project data is kept until you delete it. Deleting a project cascades to its interview, project model, generation jobs, artifacts and stored files. Deleting your account removes your organization and everything hanging off it. Backups and logs age out on their own retention schedule shortly afterwards.

An imported project's structure follows the same rule: the file names, sizes and fingerprints live as long as the project they belong to and go when it does. The file contents were never kept in the first place — they exist only for the length of the request that analysed your archive, and the archive itself stays on your own machine.

Your rights

If you are in the EU or UK you can ask for a copy of your data, correct it, have it erased, restrict or object to processing, and complain to your national supervisory authority. You can delete projects and your account yourself at any time. For anything else, write to hello@airrow.app.

Cookies

Airrow sets only the cookies it needs to work. They are listed in the cookie policy.

Changes

When this policy changes, the date at the top of the page changes with it. That date is the thing to check — we do not currently notify you in the application, and would rather say so than promise a message we have no way to send.

Airrow is in early access. These pages describe how the service actually works today. The operating entity, registered address and governing law are published here before general availability, and the date above changes whenever anything on this page does.

Privacy policy · Airrow